Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fast Uri HIGH 7.5
CVE-2026-16221

Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash…

Fix: 2.4.3 / 3.1.4+
Fix from $1,950 2026-07-19
Body Parser MEDIUM 5.9
CVE-2026-12590

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value suc…

Fix: 1.20.6 / 2.3.0+
Fix from $1,600 2026-07-09
Fast Uri HIGH 7.5
CVE-2026-13676

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a he…

Fix: 3.1.3 / 4.0.1+
Fix from $1,950 2026-06-29
Node Version Manager HIGH 7.5
CVE-2026-10796

nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands …

Fix: 0.40.5+
Fix from $1,950 2026-06-04
Webdriverio CRITICAL 9.8
CVE-2026-25244

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 cont…

Fix: 9.24.0+
Fix from $2,300 2026-05-18
Fast Uri HIGH 7.5
CVE-2026-6322

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during seriali…

Fix: 3.1.2+
Fix from $1,950 2026-05-05
Fast Uri HIGH 7.5
CVE-2026-6321

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encod…

Fix: 3.1.1+
Fix from $1,950 2026-05-04
Eslint MEDIUM 5.5
CVE-2025-50537

Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exp…

Fix: 9.26.0+
Fix from $1,600 2026-01-26
Messageformat HIGH 7.5
CVE-2025-57349

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to…

Fix: 2.3.0+
Fix from $1,950 2025-09-24
Express MEDIUM 5.3
CVE-2024-10491

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanit…

Fix: 3.21.5+
Fix from $1,600 2024-10-29
Body Parser HIGH 7.5
CVE-2024-45590

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious acto…

Fix: 1.20.3+
Fix from $1,950 2024-09-10
Packager HIGH 7.5
CVE-2024-29900

Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distr…

Patch available
Fix from $1,950 2024-03-29
Express MEDIUM 6.1
CVE-2024-29041

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected …

Fix: 4.19.2+
Fix from $1,600 2024-03-25
Electroncord HIGH 7.5
CVE-2024-26136

kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `confi…

Fix: 2024-02-19+
Fix from $1,950 2024-02-20
Express MEDIUM 6.1
CVE-2014-6393

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level respo…

Fix: after 3.10.5
Fix from $1,600 2017-08-09
Serve Index MEDIUM 6.1
CVE-2015-8856

Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script o…

Fix: 1.6.3+
Fix from $1,600 2017-01-23